VYPR

rpm package

suse/mariadb&distro=SUSE Linux Enterprise Module for Package Hub 15 SP7

pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Vulnerabilities (6)

  • CVE-2026-49261CriJun 11, 2026
    affected < 11.8.8-150700.3.15.1fixed 11.8.8-150700.3.15.1

    MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node

  • CVE-2026-34303MedApr 21, 2026
    affected < 11.8.8-150700.3.15.1fixed 11.8.8-150700.3.15.1

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protoco

  • CVE-2026-35549MedApr 3, 2026
    affected < 11.8.8-150700.3.15.1fixed 11.8.8-150700.3.15.1

    An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha

  • CVE-2026-32710HigMar 20, 2026
    affected < 11.8.6-150700.3.12.1fixed 11.8.6-150700.3.12.1

    MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code

  • CVE-2026-3494Mar 3, 2026
    affected < 11.8.8-150700.3.15.1fixed 11.8.8-150700.3.15.1

    In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) styl

  • CVE-2025-13699HigDec 23, 2025
    affected < 11.8.5-150700.3.9.1fixed 11.8.5-150700.3.9.1

    MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but